Bug#338785: mozilla-browser: mozilla fills in name/password
remembered for one form into unrelated other forms
Mike Hommey
mh at glandium.org
Sun May 13 08:08:54 UTC 2007
On Sat, Nov 12, 2005 at 07:51:54PM +0100, Marc Lehmann <debian-reportbug at plan9.de> wrote:
> Package: mozilla-browser
> Version: 2:1.7.8-1
> Severity: normal
>
>
> Mozilla fills in login/password into unrelated/different forms (different
> url and different fields). This might or might not be a serious issue, as
> mozilla doesn't check the type of the input field: maybe it is possible to
> fetch login/pw information by hidden fields. In any case, mozilla fills in
> data that originally was in a password (== write only) field into a normal
> input field (== readable), so when this would happen in a public place the
> password would be plainly visible.
Could you check if this still occurs with iceape, which replaces mozilla
in etch ?
Thanks
Mike
More information about the pkg-mozilla-maintainers
mailing list